This issue has supposedly been patched by microsoft in their Sept 26th update (KB5030310)
Reddit thread discussing positive results
I am implementing this update now and will share results in the coming days.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
In the most recent laptops that I installed the latest update of Windows 11 (22H2) every so often that I restart the computer I get the message "The security log on this system is full". I enter the event viewer with another credentials and choose the "Overwrite events" option but after a while it doesn't allow me to log in showing the same previous message and changing back to the "don't overwrite events" option.
This issue has supposedly been patched by microsoft in their Sept 26th update (KB5030310)
Reddit thread discussing positive results
I am implementing this update now and will share results in the coming days.
This is the explanation I got after submitting a support ticket:
The GP that you are using applies to 2003 and earlier. The “by days” does not work in newer OS, it basically works as “overwrite as needed”. In Windows 11 22h2 the Eventlog code was revamped, so the effect of using this policy is to set retention to “do not overwrite” if the value for Retention is anything but 0 (overwrite). By setting the policy to “by days”, it sets the retention value to days in number of seconds, so it is non-zero, thus the eventlog is set to “do not overwrite”. In combination with the size limit, it will cause the issue the customer is seeing. If you set this policy:
“Computer Configuration > Administrative Templates > Windows Components > Event Log Service > Security > Control Event Log Behavior when the log file reaches its maximum size” to “Disable” The GP will revert the behavior back to “overwrite as needed” and it should work as they were using it before. There are also other Eventlog settings in that GP location that apply to Vista and newer.
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more
Same issue,
The log security on the computer has been set to overwrite but after reboot is getting back to don't overwrite.
Also, the GPO on the computer and on Domain Controller for "Control Event Log Behavior When The Log File Reaches Its Maximum Size" have been set to Disable, but still the computer with Win 11 is getting blocked.
Hopefully Microsoft can fix this issue on Win 11 after a while.
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more